An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database.

Published : 2019-10-09 21:15 Updated : 2019-10-11 14:32

CVSS Score More info
Score 6.5 / 10
Vendor Product Version URI
Zingbox Inspector 1.288 cpe:/a:zingbox:inspector:1.288
  1. Zingbox (1) Search CVE
    1. Inspector (1) Search CVE
      1. 1.288


ID Name Description Links
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. CVE

History of changes

Date Event
2019-10-11 14:32
2019-10-09 21:15